General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4454 Views
  • 0 replies
  • 0 Likes

Resolved! Traffic originate from PaloAlto Firewall

Hello Experts - Can you clarify how to configure Paloalto firewall to source traffic from Data Interface rather than Management Interface Scenario: When Firewall send syslog message to exernal Syslog Server, the Firewall has to be configured to have Source IP address of Internal Interface instead of Management Interface. It is similar command in...

GlobalProtect timeouts.

When configuring a timeout on Globalprotect, the documentation reads: On the GlobalProtect Gateway Configuration dialog, select AgentTimeout Settings and then configure the following settings:Modify the maximum Login Lifetime for a single gateway login session. The default login lifetime is 30 days—during the lifetime, the user stays logged in a...

Windows Install Failing

Hopefully someone can help or point me in the right direction. We've been askedby one of our clients to use Global Protect but the client is failing to install on some PCs. They are running Windows 10 Pro and get the following error when trying to install

error.jpg
monkums by L1 Bithead
  • 3706 Views
  • 5 replies
  • 0 Likes

Resolved! Threat False Positives?

Our threat logs are full of 'Fallout Exploit Kit Detection' this morning from many of our networks, although no actul issues have been found.

fallout.png

Resolved! How I can stop PSIPHONE?

Dear Experts, Please can someone help me with how i can denay PSIPHONE? Its, so defcult to do that. I have enable SSH-Proxy and enable SSL-Forward. and create a rule to block SSH APPs and Proxy APPs and finlly add High Risk APPs. After all that PSIPHONE can working!! I have add the CA on my pc and browsing and I am make sure that the Decryption ...

Resolved! Best Practice - Blocking Applications at Certain times.

Greetings I am trying to find a Best Practice for blocking applications at certain times for a certain group of users. As i see it I create a policy for these users allowing them access to a few applications. now if i wanted to allow them acces to Instagram or Netlix as an example. I could 1) add Netflix in tho the allowed group, thenA) Create a...

Wykeham by L1 Bithead
  • 3018 Views
  • 2 replies
  • 0 Likes

Resolved! palo alto decryption adobe flash player connection error

Hi Few months ago I start doing SSL decryption testing on few users, One of the issue that I have which I didn't find any answer is Adobe flash player, I excluded the site https://get.adobe.com from decryption but still after downloading the flash player exe upadte file I get "connection error" from the installation. On the logs I don't see an...

adobe connection error.jpg
SShnap by L3 Networker
  • 6388 Views
  • 1 replies
  • 0 Likes

Ingress inconsistent Packet dropping

Hello, There are intermittently packet drops for the traffics destined to Internet from the trust zone. No deny log as the traffic cannot traverse through Palo Alto firewall so I can only see drop and receive logs not firewall and transmit logs from pcap. Any ideas? Best regards,Bomi

GP VPN causing slowness

recently pushed out always-on vpn, but one site/office is reporting slowness when connected to it. The office is a managed office, so i have no control over their internal network. When VPN is disabled they are able to hit 600mb download/upload. As soon as the user enables GP VPN, this cuts down to 20mbps. I have performed a packet capture on th...

welly_59 by L3 Networker
  • 2875 Views
  • 3 replies
  • 0 Likes

Relevant Zone for an IP address in Vwire

Hi Experts, Could you please suggest how to find Relevant Zone for an IP addresses in V Wire mode. When configuring security policy, we need to mention the source and destination zone. We've PA firewalls only configured in Vwire with multiple zones. Please suggest is there any way we could check it from GUI or from CLI an relevant zone for an...

PBF not working when ECMP is configured

HI I have two internet links and configured ECMP to do load balacing based on weight, Here I want to allow few users from my internal to specific desired destination based on my PBF to take my ISP2 path. But it is sometimes taking ISP 1 and sometimes ISP2 when I'm going through my ISP2 i can able to reach my destination server but fails when I'...

Multiple GlobalProtect Gateways on same interface?

We recently (today) configured pre-logon VPN, but have come across what could be a show stopper. As its currently configured we have configured: Gateway > (gateway name) > Authentication > Certificate Profile > (a client cert signed by our infrastructure) If a machine has this cert installed it now succesfully connects via "pre-logon...

welly_59 by L3 Networker
  • 6430 Views
  • 3 replies
  • 1 Likes

USERS WEB Surfing

Hello allThere is a task.The Management want to see what employers do during work time.Which sites they surf and so onWe have Palo Alto PA-850Is it possible to show them in real time which user surfing which web site.I mean real time surfing?I know that there is USER ACTIVITY REPORT.But it is not allow us to see in real time user surfing like In...

Radmin_85 by L4 Transporter
  • 2343 Views
  • 2 replies
  • 0 Likes
  • 24376 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels